Syngress - How To Cheat at Installing, Configuring and Troubleshooting Active Directory and DNS (2003).pdf

(791 KB) Pobierz
How to Cheat
This special Syngress e-book is
designed to provide quick,
step-by-step help to anybody trying
to wrestle with Win 2K Active
Directory and DNS configuration
Authors include:
Melissa Craft, Debra Littlejohn Shinder,
Ralph Crump, Paul Shields,
and David Smith
Copyright 2003 by Syngress
Publishing. All rights reserved.
DNS AND ACTIVE DIRECTORY
DNS makes Active Directory function, so the first thing you need to know is how to verify that DNS is
working, and how to install Windows 2000 DNS if it is not already on the network. Once DNS is
installed, you can configure it to meet your network’s needs. After some Domain Controllers (DCs) are
installed, you can integrate DNS zones into Active Directory, configure them with Dynamic DNS
(DDNS), and take advantage of Secure Dynamic Updates.
TOPIC 1: Installing DNS................................................................................................................ 2
TOPIC 2: Configuring Windows 2000 Domain Name System to Support Active Directory ........ 3
TOPIC 3: Setting Up a Windows 2000 Domain Controller ........................................................... 5
TOPIC 4: Locate Domain Controllers In Windows ..................................................................... 17
TOPIC 5: Promote and Demote Domain Controllers in Windows 2000...................................... 21
TOPIC 6: Design a Global Active Directory Domain and Trust Infrastructure ........................... 22
TOPIC 7: Integrating DNS into the Active Directory .................................................................. 34
TOPIC 8: Remove Data in Active Directory After a Failed Domain Controller Demotion ........ 37
TOPIC 9: Create a Child Domain in Active Directory................................................................. 38
TOPIC 10: Dynamic DNS ............................................................................................................ 39
TOPIC 11: DNS Namespace Planning ......................................................................................... 40
TOPIC 12: Modifying the Active Directory Schema ................................................................... 51
TOPIC 13: What Can Go Wrong, Will…..................................................................................... 65
TOPIC 14: Handy Active Directory Tools and Links .................................................................. 73
Copyright 2003 Syngress Publishing, all rights reserved
32464761.016.png 32464761.017.png
DNS and Active Directory
TOPIC 1: Installing DNS
Windows 2000 DNS is not installed automatically as part of the Windows 2000 Server operating system.
You can select to install DNS during the installation procedure, or you can add the DNS service later. To
add the service later:
1. Logon to the Windows 2000 server as an Administrator or equivalent.
2. Openthe Control Panel .
3. Openthe Add/Remove Programs .
4. Click Add/Remove Windows Components .
5. Select Networking Services under the Components list.
6. Click Details .
7. Check the box for Domain Name System (DNS) and click OK .
8. Click Next and insert the CD-ROM for your Windows 2000 Server software if prompted.
9. Click Finish after the DNS software files have been copied.
2
Copyright 2003 Syngress Publishing, all rights reserved
How to Cheat…
TOPIC 2: Configuring Windows 2000 Domain Name System
to Support Active Directory
If the server does not have DNS installed or configured on it, it will not have Active Directory installed
either, because Active Directory depends on locating a DNS server. To configure DNS before running the
Active Directory Wizard:
1. Eitherselect Start | Programs | Administrative Tools | DNS , or from the Windows 2000
Configure Your Server screen, select the Networking option in the left-hand pane. When it
expands, select DNS , and click the Manage DNS option in the right-hand pane that appears.
2. Select the server on which you will be configuring DNS.
3. Clickthe Action menu.
4. Choosethe Configure the Server option.
5. The Configure DNS Server Wizard appears with a Welcome screen. Click Next .
6. If this server will be a root server for DNS, select the first DNS server on the network as
shown in the following figure. If DNS is already installed and configured on the network,
select the second option.
DNS Root Server
7. The Configure DNS Server Wizard will prompt you to create a Forward Lookup Zone. If
Active Directory is installed, then you will be able to use the Active Directory-integrated
option. However, if the server is a stand-alone or member server and you attempt to create a
Forward Lookup Zone, you will see that the Active Directory Integrated option is grayed out,
as shown in the following figure. Not to worry, simply select the second option to create a
Standard Primary for now, and click Next .
Copyright 2003 Syngress Publishing, all rights reserved
3
32464761.018.png 32464761.019.png 32464761.001.png 32464761.002.png 32464761.003.png 32464761.004.png 32464761.005.png
DNS and Active Directory
Active Directory Integration Not Available as a Stand-Alone DNS Server
8. The Configure DNS Server Wizard will provide a Summary page. If you need to make
changes, you can click Back . If not, click Finish to close the wizard screen.
4
Copyright 2003 Syngress Publishing, all rights reserved
32464761.006.png 32464761.007.png 32464761.008.png 32464761.009.png 32464761.010.png 32464761.011.png 32464761.012.png
How to Cheat…
TOPIC 3: Setting Up a Windows 2000 Domain Controller
The first domain in the Active Directory forest is the root domain. This domain is special, not only
because it automatically is given all the Flexible Single Master Operations (FSMO) roles until you move
them at a later time, but also because it is the test bed for your installation routines. As you add more
domains to the forest, you will become more proficient at the process. The first domain, though, is where
you cut your teeth.
The first DC in Active Directory receives the honor of being the DC for the root domain of the
first forest. In other words, the installation of Active Directory on the first DC is the same thing as the
installation of the root domain. Performing the installation of the DC requires that you know something
about it. The following table lists the types of information needed to install the first Windows 2000 DC.
Information Required for Windows 2000 Installation
Server Information
Example
Domain name
Root.com
Server DNS name
Server.root.com
Server NetBIOS name
Server
Partition and size
C: and 2 GB
File system
NTFS
System directory
\WINNT
Name of license owner
M.Y. Name
Organization of license owner
My Org
Language
English
Keyboard
U.S.
License mode (per seat or per server)
Per seat
Administrator’s password
Hx346xqmz3
Time zone
Arizona GMT -7
Before you install DNS, you must have a static IP address assigned to the server. If you selected
all the defaults during the server installation, then you will automatically be using a DHCP address on the
server. You must change this to a static address:
1. Log on to the server as an Administrator or equivalent.
2. Openthe Control Panel .
3. Open Network and Dial-up Connections .
4. Right-click the network connection where you want to assign the IP address, likely named
Local Area Connection .
5. Click Properties in the pop-up menu.
6. Click Internet Protocol (TCP/IP) .
7. Click Properties .
8. Type in the appropriate IP address, subnet mask, and gateway addresses where indicated.
9. Clickthe Advanced button.
10. Click the DNS tab.
11. Select Append primary and connection specific DNS suffixes .
12. Check the box for Append parent suffixes of the primary DNS suff ix.
13. Check the box for Register this connection’s addresses in DNS .
Copyright 2003 Syngress Publishing, all rights reserved
5
32464761.013.png 32464761.014.png 32464761.015.png
Zgłoś jeśli naruszono regulamin